首页> 外文期刊>Journal of Information Warfare >A denial of service and some IPsec-implementations
【24h】

A denial of service and some IPsec-implementations

机译:拒绝服务和某些IPsec实现

获取原文
获取原文并翻译 | 示例
       

摘要

IP security (IPsec) is in global use for example in corporate Virtual Private Networks. It is also intended for the protection of nodes in the third generation (3G) mobile networks. Denial of Service (DOS) is a threat especially in 3G networks where availability requirements are very strict. This thesis is about identifying those threats and presenting methods for analysing IPsec implementations and their vulnerabilities so certain Denial of Service attacks. The objective of this study is to review IPsec DoS vulnerabilities, and to produce and analyse tools for this. The best entry points for DoS attacks are in IKE (Internet Key Exchange) protocol, so the scope of the study is limited so attacks against IKE. The results show that implementations differ very much from each other in robustness against chosen attacks. In some attacks the best implementations do not suffer from DoS at all, but poor implementations may even crash. Simple protections, such as hard-coded limits for memory consumption, work well against the tested DoS attacks.
机译:IP安全性(IPsec)已在全球范围内使用,例如在公司的虚拟专用网中。它还旨在保护第三代(3G)移动网络中的节点。拒绝服务(DOS)是一种威胁,尤其是在可用性要求非常严格的3G网络中。本文的主题是识别那些威胁,并提出分析IPsec实现及其漏洞的方法,从而分析某些拒绝服务攻击。这项研究的目的是审查IPsec DoS漏洞,并为此产生和分析工具。 DoS攻击的最佳切入点是IKE(Internet密钥交换)协议,因此研究范围有限,因此只能针对IKE进行攻击。结果表明,在针对所选攻击的鲁棒性方面,实现方式彼此之间有很大不同。在某些攻击中,最佳实施完全不受DoS的影响,但是不良的实施甚至可能崩溃。简单的保护措施(例如内存消耗的硬编码限制)可以很好地抵御经过测试的DoS攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号